Privacy Policy
Last updated: August 2026
OwlSuite is a business platform operated by Global BrainForce. It is used by companies to manage recruitment, client proposals, commercial agreements and workforce administration. This policy explains what we collect, how we use it, and what happens to data we access through Google APIs.
1. Information We Collect
Account information
- Your name, email address and the workspace you belong to.
- Your role and permissions within that workspace.
Business data you enter
Information you or your colleagues record in the platform — candidates, clients, leads, proposals, agreements and timesheets. This belongs to your organisation, not to us.
Google user data
If you choose to connect your Google account, we request only the permissions the feature needs:
gmail.readonly— to read messages so that correspondence with a contact appears on that contact's card.gmail.send— to send a message from your own mailbox when you write from a card, so it appears in your Sent folder and threads normally for the recipient.userinfo.email— to identify which mailbox you connected.
We do not store your whole mailbox. A message is saved only when one of its participants is a lead, client contact or candidate already recorded in your workspace.
Every other message is examined in memory and discarded without being written anywhere. Your own address and your organisation's own domains are excluded from that matching, so a message between colleagues is never attached to a customer record. When you first connect, we look back at most 90 days.
For a message that does match, we store the sender and recipients, the subject, the message body, the time it was sent, and the identifiers Google uses to thread it.
2. How We Use Your Information
- To operate the platform and the features you use.
- To show correspondence with a lead, client or candidate on that record, so your colleagues have the context.
- To send a message you compose, from your own mailbox.
- To notify you about activity relevant to your work.
- To provide support when you ask for it.
We do not use Google user data for advertising. We do not use it to train, develop or improve machine learning or artificial intelligence models, and we do not send it to any third-party AI provider.
3. Sharing of Information
We do not sell personal data or Google user data, to anyone, for any purpose.
Data recorded in a workspace is visible to that workspace's members according to their permissions. Card correspondence is shared with your team by default — that is the purpose of putting it on a shared record — and you can mark an individual message private, which hides it from everyone but you.
We share data outside your workspace only with:
- infrastructure providers that host the platform and its database, under contract and solely to run the service;
- an email delivery provider, for system messages such as invitations and acknowledgements;
- authorities, where the law requires it.
Google user data is never transferred for any purpose unrelated to the features described above.
4. Data Protection and Security
- OAuth tokens are encrypted at rest with AES-256-GCM before they are stored, and are decrypted only in the moment a request to Google is made. They are never returned to a browser and never appear in our interfaces.
- Data is transmitted over TLS.
- Each workspace's data is isolated, so one organisation cannot read another's.
- Access within a workspace is governed by roles and per-feature permissions, enforced on the server.
No system is perfectly secure, and we do not claim otherwise. We design so that a failure exposes as little as possible.
5. Data Retention and Deletion
We keep data for as long as your organisation uses the platform, and for as long as it is needed for the purposes above.
You can disconnect your Google account at any time, from Email connection in the application. Disconnecting stops all further access immediately: we end the subscription that notifies us of new mail, revoke our access at Google, and delete the stored tokens.
Messages already synced to a record remain there, because they are your organisation's record of its correspondence with that customer — in the same way an email in a shared inbox does not disappear when a colleague leaves. If you want that history removed as well, ask us and we will delete it.
You may request deletion of your account and associated personal data at any time via the address below.
6. Your Rights and Choices
- Review and correct the information held about you.
- Connect or disconnect your Google account whenever you choose; the feature is entirely optional.
- Mark individual messages private.
- Request a copy of your personal data, or its deletion.
- Object to how we process your data, or raise a concern with your data protection authority.
7. Third-Party Services and Google API Limited Use
OwlSuite uses Google APIs to provide the mailbox features described above.
OwlSuite's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Changes to This Policy
If we change how we handle data, we will update this page and the date at the top. Material changes affecting Google user data will be communicated to workspace administrators.
9. Contact Us
Questions about this policy, or a request concerning your data: [email protected]